Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.68% | — | Openlibraryfoundation VufindAI | 22/5/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files to gain access to the administrator panel and achieve Remote Code Execution. A mitigating factor is that it… | |
| Aplazada | Media (5.4) | 0.45% | — | Openlibraryfoundation VufindAI | 22/5/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open Library Foundation VuFind 2.4 through 9.1 before 9.1.1 allows remote attackers to access internal HTTP servers and perform Cross-Site Scripting (XSS) attacks by proxying arbitrary URLs via the proxy… | |
| Aplazada | Media (5.4) | 0.31% | — | Yoast Custom Field FinderAI | 29/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3. | |
| Modificada | Alta (8.8) | 0.58% | — | Markusseyer Find Duplicates | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Markus Seyer Find Duplicates.This issue affects Find Duplicates: from n/a through 1.4.6. | |
| Analizada | Media (6.5) | 0.58% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/applicants/index.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/applicants/controller.php. The manipulation of the argument JOBREGID leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Campcodes Online Job Finder System 1.0. This affects an unknown part of the file /admin/applicants/index.php. The manipulation of the argument view leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Campcodes Online Job Finder System 1.0. Affected by this issue is some unknown functionality of the file /admin/category/index.php. The manipulation of the argument view leads to cross site scripting. The attack may be launched remotely. The… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Online Job Finder System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/company/index.php. The manipulation of the argument view leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Campcodes Online Job Finder System 1.0. Affected is an unknown function of the file /admin/employee/controller.php. The manipulation of the argument EMPLOYEEID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/employee/index.php. The manipulation of the argument view leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/user/index.php. The manipulation of the argument view leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.1) | 0.62% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/vacancy/index.php. The manipulation of the argument view leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.50% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/applicants/controller.php. The manipulation of the argument JOBREGID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.50% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation of the argument CATEGORYID leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.5) | 0.53% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Online Job Finder System 1.0. Affected is an unknown function of the file /admin/company/controller.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.5) | 0.50% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Campcodes Online Job Finder System 1.0. This issue affects some unknown processing of the file /admin/company/index.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.5) | 0.58% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability classified as critical was found in Campcodes Online Job Finder System 1.0. This vulnerability affects unknown code of the file /admin/employee/index.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.5) | 0.58% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Job Finder System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.5) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/controller.php. The manipulation of the argument UESRID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/user/index.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.58% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/vacancy/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.5) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/employee/controller.php of the component GET Parameter Handler. The manipulation of the argument EMPLOYEEID leads to sql injection. The attack may be initiated… | |
| Analizada | Media (6.5) | 0.60% | — | Campcodes Online JOB Finder System | 20/3/2024 | 17/6/2026 | A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/vacancy/controller.php. The manipulation of the argument id/CATEGORY leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.32% | — | Doofinder | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder for WooCommerce allows Stored XSS.This issue affects Doofinder for WooCommerce: from n/a through 2.1.8. |